Identify
Understanding what you hold and what threatens it: assets, business services, suppliers, and the risk register.
- Asset inventory
- Business catalog
- Risk register
- Supply chain
Five functions that summarise posture without hiding the detail underneath, which is why it survives contact with a board. In Sentinel Unity the function-level number stays connected to the controls and evidence that produced it.
Published by the National Institute of Standards and Technology. Widely used as a reporting layer over whichever control set you actually run.
Level 3: Well Defined
A standard process is defined and followed across the organisation.
Every question in the control library carries its own written descriptor at each level.
Five
Core functions
0 to 5
Maturity scored
Graded
Mapping to other standards
Traceable
Function score to control
Core functions
Each function is a view over controls the platform already holds, not a separate programme to staff.
Understanding what you hold and what threatens it: assets, business services, suppliers, and the risk register.
The safeguards themselves, which is where policy, access rights, and control testing concentrate.
Noticing in time, which in governance terms means indicators with thresholds rather than quarterly reporting.
What happens once something is found: findings, owners, severity, and a plan with a sequence.
Restoration and what was learned, including loss events recorded against the risk that produced them.
Platform mapping
Function-level posture is computed from the same controls the rest of the programme assesses, so two numbers cannot drift apart.
Key risk and performance indicators carry their own thresholds, so a breach is raised as an event rather than noticed at review.
Findings carry severity, owners, and remediation plans that can depend on one another, making the order of work explicit.
Actual losses are recorded against the risk, which is what turns an estimate into something you can check afterwards.
Report schedules, share links with an access log, webhook subscriptions, and BI export, generated from live data.
Where a control is mapped to another framework, the assessment behind it is not repeated for the sake of a different cover page.
Maturity
Every control behind a function is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.
Level 0
Not Performed
The practice does not happen. Recorded as an explicit level rather than a blank.
Level 1
Performed Informally
It happens, but it depends on individuals and is neither planned nor tracked.
Level 2
Planned & Tracked
Planned, resourced, and monitored, though practice still varies between teams.
Level 3
Well Defined
A defined standard process, applied consistently across the organisation.
Level 4
Quantitatively Controlled
Measured against targets, with deviation detected from the measurements themselves.
Level 5
Continuously Improving
Improvement is fed by the measurements, changing the process rather than the reporting.
Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.
No commitment required. A typical demo runs 45 minutes.